/ ip firewall filter
| add chain=input protocol=tcp dst-port=22 src-address-list=black_list action=drop \ comment="drop ssh brute forcers" disabled=no add chain=input protocol=tcp dst-port=22 connection-state=new \ src-address-list=ssh_stage3 action=add-src-to-address-list address-list=black_list address-list-timeout=1d \ comment="" disabled=no add chain=input protocol=tcp dst-port=22 connection-state=new \ src-address-list=ssh_stage2 action=add-src-to-address-list address-list=ssh_stage3 address-list-timeout=1m \ comment="" disabled=no add chain=input protocol=tcp dst-port=22 connection-state=new \ src-address-list=ssh_stage1 action=add-src-to-address-list address-list=ssh_stage2 address-list-timeout=1m \ comment="" disabled=no add chain=input protocol=tcp dst-port=22 connection-state=new \ action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=1m comment="" \ disabled=no |
ftp blocker
/ ip firewall filter
| add chain=input protocol=tcp dst-port=21 src-address-list=black_list action=drop \ comment="drop ftp brute forcers" disabled=no add chain=input protocol=tcp dst-port=21 connection-state=new \ src-address-list=ftp_stage3 action=add-src-to-address-list address-list=black_list address-list-timeout=1d \ comment="" disabled=no add chain=input protocol=tcp dst-port=21 connection-state=new \ src-address-list=ftp_stage2 action=add-src-to-address-list address-list=ftp_stage3 address-list-timeout=1m \ comment="" disabled=no add chain=input protocol=tcp dst-port=21 connection-state=new \ src-address-list=ftp_stage1 action=add-src-to-address-list address-list=ftp_stage2 address-list-timeout=1m \ comment="" disabled=no add chain=input protocol=tcp dst-port=21 connection-state=new \ action=add-src-to-address-list address-list=ftp_stage1 address-list-timeout=1m comment="" \ disabled=no |
/ ip firewall filter
comment="drop telnet brute forcers" disabled=no
add chain=input protocol=tcp dst-port=23 connection-state=new \
src-address-list=telnet_stage3 action=add-src-to-address-list address-list=black_list address-list-timeout=1d \
comment="" disabled=no
add chain=input protocol=tcp dst-port=23 connection-state=new \
src-address-list=telnet_stage2 action=add-src-to-address-list address-list=telnet_stage3 address-list-timeout=1m \
comment="" disabled=no
add chain=input protocol=tcp dst-port=23 connection-state=new \
src-address-list=telnet_stage1 action=add-src-to-address-list address-list=telnet_stage2 address-list-timeout=1m \
comment="" disabled=no
add chain=input protocol=tcp dst-port=23 connection-state=new \
action=add-src-to-address-list address-list=telnet_stage1 address-list-timeout=1m comment="" \
disabled=no
-----------------hemmm gimana klo misalnya dibikin suatu firewall yang hanya memperbolehkan alamat tertentu saja yang boleh mengakses router selain itu di drop.
misal untuk yang diperbolehkan untuk mengakses router adalah komputer administrator dengan ip 192.168.0.1
contoh firewall yang akan dibangun :
/ip firewall filter add chain=input src-address=192.168.0.1 action=accept
/ip firewall filter add chain=input action=drop





























PT Yamaha Motor Kencana Indonesia (YMKI) kembali meluncurkan salah satu varian terbaru. Bebek matik yang diberinama Lexam ini memiliki fitur komplit dan teknologi yang dibenamkan benar-benar baru dan canggih. Disamping itu, Yamaha Lexam menawarkan kenyamanan dan keamanan saat berkendara. Sementara, pada sektor suspensi depan, Lexam unggul karena menggunakan dua buah pegas didalam tabung teleskopiknya. Hal ini membuat pengendara semakin nyaman karena minimnya getaran yang ditumbulkan saat melintasi jalan bergelombang atau rusak.
















